[
https://issues.apache.org/jira/browse/GEODE-10592?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18099828#comment-18099828
]
ASF subversion and git services commented on GEODE-10592:
---------------------------------------------------------
Commit 978012290cb09e90c1d2adbb00801adc440965d3 in geode's branch
refs/heads/develop from Jinwoo Hwang
[ https://gitbox.apache.org/repos/asf?p=geode.git;h=978012290c ]
[GEODE-10592] Remediation of CVE-2026-40984 (#8018)
* Remediation of CVE-2026-40984
* CI build failure
* Update CodeQL and actions to specific versions (v4.2.2/v4.7.1) to resolve
Node.js 24 warnings
> Remediation of CVE-2026-40984
> -----------------------------
>
> Key: GEODE-10592
> URL: https://issues.apache.org/jira/browse/GEODE-10592
> Project: Geode
> Issue Type: Improvement
> Reporter: Jinwoo Hwang
> Assignee: Jinwoo Hwang
> Priority: Major
>
> Affected versions of this package are vulnerable to Allocation of Resources
> Without Limits or Throttling via HTTP server metrics instrumentation in
> Micrometer. An attacker can cause denial of service by sending specially
> crafted HTTP requests that trigger excessive resource consumption during
> metrics collection and processing. Repeated requests can degrade application
> performance and potentially render the service unavailable.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)